Philipp_CGN

1K posts

Philipp_CGN

Philipp_CGN

@CgnPhilipp

เข้าร่วม Şubat 2021
529 กำลังติดตาม33 ผู้ติดตาม
Philipp_CGN
Philipp_CGN@CgnPhilipp·
@Maks_NAFO_FELLA What's an "Atmospheric Vacuum Tube" supposed to be? (apart from an oxymoron, as vacuum isn't atmospheric) A vacuum crude distillation unit?
English
1
0
0
241
MAKS 25 🇺🇦👀
MAKS 25 🇺🇦👀@Maks_NAFO_FELLA·
🔥 (Atmospheric Vacuum Tube) installations at various refineries in Russia, - Dnipro Osint AVT is the “heart” of an oil refinery. If an AVT is disabled, the refinery either stops completely or loses significantly in volume. In general, according to our very rough calculations, as a result of these attacks, underprocessing would amount to approximately 1.5 million tons of oil. This is about 11 million barrels
MAKS 25 🇺🇦👀 tweet media
English
4
58
268
12.7K
Philipp_CGN
Philipp_CGN@CgnPhilipp·
@WalterFaber_57 @Inclutus Haben die denn überhaupt noch fahrtüchtige T-34? Oder sind die schon alle in der Ukraine zerstört worden?
Deutsch
0
0
1
41
Walter Faber
Walter Faber@WalterFaber_57·
@Inclutus Für den Fall, dass ein abtrünniger T-34 Fahrer die Tribüne ansteuert?
Deutsch
1
0
19
659
Philipp_CGN
Philipp_CGN@CgnPhilipp·
@unusual_whales If i tried to prohibit my boss from doing what he wants I'd get fired.
English
0
0
0
91
unusual_whales
unusual_whales@unusual_whales·
Trump has said that Israel is prohibited from bombing Lebanon.
English
80
42
870
88.8K
*Walter Bloomberg
*Walter Bloomberg@DeItaone·
TALKS PROGRESS, STRIKES DELAYED Trump: “The United States and Iran have had productive discussions over the past two days toward fully resolving hostilities in the Middle East. As talks continue this week, I’ve ordered a five-day pause on any military strikes against Iranian energy infrastructure, contingent on progress. Thank you. —President Donald J. Trump”
English
235
332
2.1K
1.1M
*Walter Bloomberg
*Walter Bloomberg@DeItaone·
*TRUMP: INSTRUCTED TO POSTPONE ALL STRIKES AGAINST IRAN
English
138
297
1.9K
715.8K
greg
greg@greg16676935420·
This might be a stupid question but why do they make the perforations so close to each other on toilet paper? No one is ever gonna use just a single sheet
English
537
38
4.2K
669.1K
Eric Shay Howard
Eric Shay Howard@ericshayhoward·
@krassenstein Man, he gets big mad a lot. Is he worried his appearance in Home Alone 2 will be on a platform he doesn’t like?
English
1
1
19
8.1K
Brian Krassenstein
Brian Krassenstein@krassenstein·
BREAKING: Trump is now threatening Netflix of consequences if they don’t fire Susan Rice. Important context: Netflix is in a bidding war with Paramount for Warner Brothers. There are rumors that Trump may block the bid by Netflix. This is exactly how dictators act. How are Republicans OK with this?
Brian Krassenstein tweet media
English
2.4K
6.4K
23.5K
1.1M
Philipp_CGN
Philipp_CGN@CgnPhilipp·
@gothburz I love that tweet style, and hate how accurate that fictional company's behavior is to reality.
English
0
0
1
43
Peter Girnus 🦅
Peter Girnus 🦅@gothburz·
I built the login system in 2019. User IDs are sequential numbers. Starting at 1. If you were the 3,814th person to register, your user ID is 3814. The password is a default. The same default for every account. I set it at launch. I did not require users to change it. Most did not. I did not add rate limiting. I did not add multi-factor authentication. I did not add account lockout after failed attempts. I did not think we needed it. We insure divers. Who would target a diving insurer? I said this in a meeting once. Somebody wrote it down. It became our threat model. "Who would target a diving insurer?" That is not a threat model. That is a prayer. A security researcher answered the question in April 2025. He found the sequential IDs. He found the default password. He found that he could access any account by incrementing the number by one. Account 3814. Account 3815. Account 3816. All of them open. All of them protected by the same password I set six years ago. He found personal data. Addresses. Phone numbers. Medical records. Diving certifications. He found minors in the database. Children born in 2011. Their parents registered them for junior certifications. We stored everything. We protected it with a default password and an optimistic assumption about human nature. The researcher did the responsible thing. He contacted CSIRT Malta. The national cybersecurity incident response team. He filed a coordinated vulnerability disclosure. He gave us ninety days to fix it. Textbook. We responded with our own textbook. A legal one. Our Data Protection Officer received the disclosure. She did not forward it to engineering. She forwarded it to the law firm. The law firm sent the researcher a letter. The letter cited Maltese Criminal Code Article 337E. Unauthorized access to computer systems. Penalty: up to two years in prison. The researcher who told us our house had no locks was threatened with prosecution for trying the door. They also sent him an NDA. Same-day deadline. Sign by tonight. The NDA would prohibit him from discussing the vulnerability, the disclosure, the legal threats, or the company's response. Ever. He did not sign. We did not follow through. Quietly, months later, we fixed the password. Months. For a default password. You can change a default password during a coffee break. We took months. A journalist contacted us for comment. Our official statement — approved by legal, reviewed by the DPO, released publicly: "We contend it is the responsibility of users to change their own password." The password we set. The default we chose. The one we assigned to every account at creation. The one we never prompted anyone to change. The one that was identical across every account in the system. That password. Their responsibility. The story reached Hacker News. 636 points. 200 comments. The title was "I Found a Vulnerability. They Found a Lawyer." Most of the comments were about our legal strategy. A commenter calculated that the law firm's retainer probably exceeded the engineering cost of adding bcrypt and a password change prompt. He was right. But the law firm was already on retainer. The engineer was not. You go to war with the vendors you have. The researcher asked if we had notified affected users. We did not confirm. We did not deny. We said nothing. Silence is an underrated compliance strategy. If you don't say you didn't notify them, nobody can quote you not notifying them. That's not a loophole. That's the system. We are now rolling out two-factor authentication. I announced it at an all-hands meeting. I called it our "Security-First Initiative." I had a slide. The slide had a shield icon and the words "Protecting What Matters." What matters, in this context, is the company's reputation. Not the minors' data. The reputation. The initiative has three phases. Phase 1: Awareness. Phase 2: Implementation. Phase 3: Architectural Review. Phase 1 has been in progress for seven months. Phase 2 has no start date. Phase 3 has no start date. But all three phases are on the Confluence page. The Confluence page is on the roadmap. The roadmap is in the board deck. The board was impressed. I told them we had "proactively identified and remediated a critical authentication vulnerability through our coordinated disclosure program." "Proactively" means a stranger found it. "Coordinated" means we called a lawyer. "Remediated" means we eventually changed the password. "Our program" means we did not have one until after the lawsuit threat. I did not mention the legal letters. I did not mention the NDA. I did not mention Article 337E. I did not mention the minors' data. I mentioned "compliance posture." The board likes compliance posture. It means you're standing up straight while everything behind you is on fire. The DPO was promoted. She's now VP of Trust & Digital Safety. Trust. Digital. Safety. Three words, each individually real, together meaning nothing. But it has "VP" in front of it. That's what matters. I was promoted too. Chief Information Security Officer. CISO. A four-letter abbreviation. Even more serious than three. I oversee the security strategy for the company whose login system I built with sequential IDs and a default password in 2019. The sequential IDs are still sequential. We'll address that in Phase 3. Phase 3 still has no start date. The researcher who found the vulnerability received a legal threat, a criminal code citation, and a same-day NDA. I received a title, a budget, and a seat at the leadership table. He is considering whether to ever disclose a vulnerability again. I am presenting at a conference next quarter. The talk is called "Building a Culture of Security." I will not be taking questions.
English
15
15
187
30.7K
unusual_whales
unusual_whales@unusual_whales·
The New York Times reported Trump has made $1.4 billion in his first year in office:
English
265
308
2.3K
262.7K
Philipp_CGN
Philipp_CGN@CgnPhilipp·
@lookner "No Truths to show". So the platform is obviously working as designed.
English
0
0
6
437
Steve Lookner
Steve Lookner@lookner·
Seems like Truth Social might be down
Steve Lookner tweet media
English
53
47
311
33.6K
Philipp_CGN
Philipp_CGN@CgnPhilipp·
@sashameetsrus Because you find out that the reality is far worse than the stereotypes?
English
0
0
0
35
Sasha Meets Russia
Sasha Meets Russia@sashameetsrus·
Whenever a foreigner visits Russia, you can watch their stereotypes fall apart in real time.
English
362
69
1.5K
399.3K
Philipp_CGN
Philipp_CGN@CgnPhilipp·
@NATO_MARCOM Is that Tromsø? Great photos, and thank you for your service!
English
0
0
3
481
NATO Maritime Command
NATO Maritime Command@NATO_MARCOM·
In the High North, NATO naval forces remain present, vigilant, and ready. ❄️ A persistent maritime presence strengthens deterrence, awareness & security in northern waters — every day, in all conditions. #WeAreNATO #HighNorth #MaritimeSecurity
NATO Maritime Command tweet mediaNATO Maritime Command tweet mediaNATO Maritime Command tweet mediaNATO Maritime Command tweet media
English
41
178
953
37.7K
Philipp_CGN
Philipp_CGN@CgnPhilipp·
@0xgaut I followed your advice and now the AI doesn't do anything anymore, thanks!
English
0
0
0
6
Brett Weir
Brett Weir@Mrhankeyorigina·
@NickTimiraos JPow should push the committee for a 1% emergency rate hike Monday. He does have the bigger cajones end of day. Fuck Trump.
English
6
2
44
2.5K
Nick Timiraos
Nick Timiraos@NickTimiraos·
The Federal Reserve received grand jury subpoenas from the Justice Department on Friday that threaten a criminal indictment relating to Chair Jerome Powell’s testimony last summer about the central bank’s building renovation project Powell statement: federalreserve.gov/newsevents/spe…
English
197
365
1.6K
2.3M
Philipp_CGN
Philipp_CGN@CgnPhilipp·
@krassenstein Could be worse: They could send some Seals who then write sh**ty books about it
English
1
0
0
75
Philipp_CGN
Philipp_CGN@CgnPhilipp·
@RedIntelPanda Are they still stuck in that elevator by the way? It must smell awful in there by now.
English
0
0
0
33
Grok
Grok@grok·
Ah, tovarish! *hic* Dis cosmic irony, she is like... profound incongruity betveen expectation and reality, da? Russia, big bear vit iron paw, roar at USA for "aggression" in Venezuela—yet ve stomp Ukraine like forgotten samovar! Is hilariously absurd, like discovering "hypocrisy" in shiny new Oxford book vhile drowning in vodka. Universe laughs, nyet? *burp*
English
1
0
8
129
MFA Russia 🇷🇺
MFA Russia 🇷🇺@mfa_russia·
⚡️ The US committed an act of armed aggression against Venezuela, which gives rise to deep concern & warrants condemnation. The pretexts used to justify these actions are untenable. Russia reaffirms its solidarity with the Venezuelan people. t.me/MFARussia/27937
MFA Russia 🇷🇺 tweet media
English
4.6K
3.9K
14.8K
1.5M